Ransomware victim disclosure
← All victimsKyodo USA
Claimed by Akira · listed 4 days ago
Status timeline
- ListedSep 9, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Sector
- Manufacturing
- Listed on leak site
- Sep 9, 2026
About the victim
AI dossier — public-source company profileKyodo USA is a distributor of marine engine spares and ship operation equipment with over 20 years of experience in the international maritime industry. The company serves more than 300 clients across 100+ countries.
- Industry
- Marine Equipment & Spares Distribution
- Employees
- 300+
Attack summary
Severity: high — Confirmed exfiltration of 30 GB including PII at scale (SSNs, government IDs for 300+ employees), financial data, and customer information from a business serving hundreds of clients globally.Akira claims to have exfiltrated approximately 30 GB of corporate data, including employee personal documents (driver's licenses, passports, SSNs), financial records, customer files, NDAs, and confidential business files.
Data the group says was taken
AI dossier — extracted from the leak post- Employee personal identification documents (driver's licenses, passports)
- Social Security Numbers
- Financial records
- Customer files and contacts
- Agreements and NDAs
- Confidential business files
- Project documentation
What the group claims
Kyodo USA is a leading distributor of marine engine spares and ship operation equipment, boasti ng over 20 years of experience in the international maritime industry. The company serves over 300 clients across more than 100 countries, providing a highly diversified product line and rel iable services. We will upload 30gb of corporate data soon. Detailed employee personal docs scans (DLs, passpor ts, SSNs and other information), contacts and agreements, financials, confidential files, custo mer files, projects, NDAs and so on.
Source
Indexed 4 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

